7.2

CVE-2006-4447

X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.

Data is provided by the National Vulnerability Database (NVD)
X.OrgEmu-linux-x87-xlibs Version7.0_r1
X.OrgX11r6 Version6.7.0
X.OrgX11r6 Version6.8
X.OrgX11r6 Version6.8.1
X.OrgX11r6 Version6.8.2
X.OrgX11r7 Version1.0
X.OrgX11r7 Version1.0.1
X.OrgX11r7 Version1.0.2
X.OrgXdm Version1.0.3
X.OrgXf86dga Version1.0.0
X.OrgXinit Version1.0.2_r5
X.OrgXload Version1.0.0
X.OrgXorg-server Version1.02_r5
X.OrgXterm Version214
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.394
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C